CVE Database
/

CVE-2023-46215

Back to search

CVE-2023-46215

Published: Oct 28, 2023

Modified: Jun 12, 2025

PUBLISHED

Description

Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Note: the vulnerability is about the information exposed in the logs not about accessing the logs. This issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3. Users are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.

VendorProductVersions

Apache Software Foundation

Apache Airflow Celery provider

affected
3.3.0 - <= 3.4.0

Apache Software Foundation

Apache Airflow

affected
1.10.0 - < 2.7.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now